What it does
Covers what has to be true before Copilot works well and safely: the technical prerequisites, and — more importantly — the data hygiene that stops Copilot surfacing content people shouldn't reach.
Key facts
- Technical baseline: Entra ID accounts, current Microsoft 365 Apps, Teams, OneDrive, and the search/Graph plumbing Copilot draws on.
- Copilot respects existing permissions — it never grants new access, but it will happily surface anything a user can already reach. Oversharing is the real risk.
- SharePoint and OneDrive sprawl, broken permission inheritance and "share with everyone" links become search hits inside Copilot.
- Purview sensitivity labels and DSPM for AI help constrain what Copilot returns and flag exposure.
- Restricted content discovery / SharePoint Advanced Management help rein in oversharing at scale.
When to use / skip
Never skip readiness. The technical bits are quick; the data-prep is the project. Enabling Copilot on a messy tenant is the fastest way to a bad first impression.
Configuration decisions
- How aggressively to remediate oversharing before enablement versus running in parallel.
- Whether sensitivity labels are in place and enforced ahead of go-live.
- Which sites to exclude from Copilot/search while they're cleaned up.
Gotchas
- The classic incident: a user asks Copilot an innocuous question and it cites the salary spreadsheet nobody realised was open to all.
- Readiness is treated as an IT checkbox; the data cleanup is org-wide and takes longer than anyone budgets.
Consultant notes
- Run an oversharing assessment before a single licence lands — it's the difference between a smooth launch and an incident.
- Budget data-prep as its own workstream with a business owner, not a task on IT's list.
- Sensitivity labels earn their keep here; get the scheme agreed before Copilot, not during.
- Stage a "restricted" phase — clean the worst sites, exclude the rest — rather than waiting for perfection.
Recheck when Purview oversharing tooling or the requirements list changes.